Gadget

Lightwell fixes flaws in open-source

Lightwell, an open-source software security platform that can automate vulnerability fixes at scale, is now commercially available. The platform, launched by IBM and Red Hat, includes two offerings.

“Lightwell Network gives enterprises access to a launch catalogue of more than 6,500 remediated, digitally signed, and certified application-layer dependencies across major ecosystems, including Java and Python,” say the companies. “Lightwell Clearinghouse Premier enters a limited-availability phase, serving as a trusted intermediary for secured patch embargoes and vertical threat co-ordination.”

The launch follows IBM and Red Hat’s $5-billion open-source security commitment announced earlier this year (May 2026). More than 20,000 engineers are supporting the development and expansion of Lightwell’s AI-assisted vulnerability remediation capabilities.

Lightwell applies Red Hat’s existing enterprise security model to organisations’ wider open-source software portfolios. IBM and Red Hat developed the platform with financial services companies and other industry partners.

“To deliver this trust infrastructure, Lightwell leverages the high-throughput capability of a generative AI-powered remediation engine that is already live and operating at scale. This advanced, AI-driven automation pipeline combines frontier and open AI models with human engineering expertise to identify, validate, and remediate vulnerabilities across critical dependencies embedded deep within modern software architectures.”

Lightwell aims to remove the friction between rapid innovation and enterprise compliance by securing the specific software packages organisations run in active production today, while establishing a stable platform for future applications. To break the dependency remediation deadlock, Lightwell uses automation to backport critical fixes directly to specific, long-lived production software versions, helping address lengthy regression testing and breaking changes that often paralyse teams forced to adopt major upstream upgrades. Red Hat and IBM expect Lightwell’s catalogue of remediated packages to scale rapidly from thousands to millions.

Red Hat and IBM provide the following information:

Lightwell operates under Red Hat’s upstream-always model, in which security fixes are actively submitted back to the originating open source community for review and acceptance. This supports commercial protections and community health continually reinforce one another, which can prevent project fragmentation without risking in-production zero days.

Scott DePasquale, ARC president and CEO, says: “No single institution can keep pace with the growing scale and complexity of open source vulnerabilities alone. The financial sector has long demonstrated the value of collaboration in addressing shared security challenges, and initiatives that enable co-ordinated remediation have the potential to strengthen resilience across the industry.”

Matt Hicks, Red Hat president and CEO, says: “Lightwell represents a fundamental structural shift in how we secure all enterprise software. By pairing automated remediation with our deep engineering heritage, we aim to deliver the trusted infrastructure required to consume open source reliably, sustainably, and at AI speeds.”

Rob Thomas, IBM software SVP and chief commercial officer, says: “IBM and Red Hat are giving enterprises certified fixes they can pull straight into the systems they already run, with no retooling or disruption, backed by a growing network of technology and delivery partners. Making that possible takes scale most organisations don’t have, a world-class team of engineers and AI systems working around the clock to protect the open source software the world’s enterprises run on.”

Jerry Silva, program vice president for IDC Financial Insights, says: “Heavily regulated industries such as financial services have the highest cost of compliance, meaning that they take security extremely seriously, especially in its use of open source software. The partnership bringing Red Hat and IBM together under the Lightwell banner to identify, triage, and remediate vulnerabilities will bolster the security and resiliency posture of these organisations globally, ensuring the trust that is the hallmark of the services they provide.”

With open source comprising up to 90% of enterprise codebases and driving 9.8-trillion downloads in 2025 alone, massive volume and $50 AI-generated exploits have broken traditional patch management, leaving codebases with an average of 581 vulnerabilities. Lightwell is designed to mitigate this unmapped risk and neutralise execution bottlenecks by evaluating application context and dependency interactions to deliver validated fixes directly into active workflows.

According to the companies, safeguarding the open source software supply chain requires an open, diverse ecosystem spanning AI models, development tools, and enterprise infrastructure. Lightwell is supported by a growing network of technology and deployment partners. By collaborating with these industry leaders, Lightwell can deliver a true orchestrated defence, enabling network rules, cloud environments, and deployment pipelines to be updated simultaneously across the entire enterprise fabric when a fix is ready.

The companies provide the following information:

* To learn more about Lightwell, visit the IBM website here and the Red Hat website here.

Exit mobile version